Hi All
I want to set my Splunk server to keep logs active for 30 days then compress those logs, save it in another directory active for 90 days.
what i know after some searches that all that configuration can be done from indexex.conf file but i didn't understand what is hot, cold & frozen, what is maxhotIdlesecs??
little help will be appreciated.
You should read this for details on how Splunk stores data:
http://docs.splunk.com/Documentation/Splunk/4.3.1/admin/HowSplunkstoresindexes
Info on maxhotIdlesecs:
http://splunk-base.splunk.com/answers/63323/how-does-the-attribute-maxhotidlesecs-work